• krigo666@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    arrow-down
    5
    ·
    22 hours ago

    And this why Secure Boot can’t be trusted. It is Micro$lop that signs and issues the keys.

      • Grass@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        17 hours ago

        wasn’t there some dumb shit like every linux distro using fedora keys which were from microsoft?

        • Hugging Stars@programming.dev
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          8 hours ago

          Microsoft signs Red Hat certs then Red Hat signs everyone’s certs, so the only thing Microsoft can do is to revoke Linux as a whole.

          It’s the solution that requires minimal user effort since most computers are designed for Windows.

          • Appoxo@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 hours ago

            And MS probably won’t do it willy-nilly because their stack is peobably using it to some degree and many more of those Fortune-X00 are very likely something RHEL. So fucking that over will crash their stock like it did with CrowdStrike but much much worse.

            • Masterkraft0r@discuss.tchncs.de
              link
              fedilink
              English
              arrow-up
              1
              ·
              4 hours ago

              not only likely… i read somewhere that make more money with linux stuff on azure than with anything else they do can’t find the source rn tho

        • sorter_plainview@lemmy.today
          link
          fedilink
          English
          arrow-up
          1
          ·
          12 hours ago

          I think it is just chain of trust. Many used Microslop as the trust authority (may be due to convenience? I have no idea). Debian has a nice page on Secure boot and how it works.

    • 9tr6gyp3@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      ·
      edit-2
      21 hours ago

      You can use custom keys with secure boot. Any PC newer than 2015 should give you that option.

      You don’t have to use Microsoft’s keys.

      This isn’t a secure boot issue. This is a bootloader issue.